Django में Password Hashing
user = User.objects.get(username='name')
user.set_password('new_password')
user.save()
user.check_password('password')
Hashing क्यों मायने रखता है
अगर एक database कभी leak हो, hashed passwords एक attacker के लिए बिना enormous computing effort के useless हैं, plain text passwords के विपरीत जो instantly readable हैं।
उदाहरण: Why Hashing Matters
create_user() runs the password through Django's hasher automatically — the stored value is never the raw text.
python manage.py shell
>>> from django.contrib.auth.models import User
>>> user = User.objects.create_user(username='bob', password='SecurePass1')
>>> print(user.password)
pbkdf2_sha256$600000$...
⚠️ Run this in your own terminal or Node.js environment.
एक Password सुरक्षित रूप से बदलना
set_password() एक नया password फिर से hash करता है और इसके बाद change persist करने के लिए save() call होना चाहिए।
set_password() के बाद हमेशा save() call करें — यह otherwise सिर्फ in-memory object update करता है।उदाहरण: Changing a Password Safely
set_password() hashes the new password in memory; save() writes the hashed value to the database.
python manage.py shell
>>> user.set_password('EvenSaferPass2')
>>> user.save()
⚠️ Run this in your own terminal or Node.js environment.
एक Password Verify करना
check_password() एक plain-text attempt को stored hash के against सुरक्षित रूप से compare करता है, True या False return करते हुए।
उदाहरण: Verifying a Password
check_password() re-hashes the guess and compares hashes, so the real password is never exposed in the process.
python manage.py shell
>>> user.check_password('EvenSaferPass2')
True
>>> user.check_password('WrongGuess')
False
⚠️ Run this in your own terminal or Node.js environment.
- Plain-text passwords एक CharField में store करना बजाय Django के User model को इन्हें अपने आप hash करने देने के।
user.passwordको सीधे एक submitted password string से compare करना बजायcheck_password()याauthenticate()उपयोग करने के।- एक custom hashing function रोल करना बजाय Django के built-in, well-tested
PASSWORD_HASHERSपर भरोसा करने के।
- Django PASSWORD_HASHERS में listed algorithms (default रूप से PBKDF2) उपयोग करके passwords अपने आप hash करता है।
- create_user() और set_password() password को hash करते हैं; .password को directly assign करना ऐसा नहीं करता।
- check_password() एक plain password को stored hash के against verify करता है बिना इसे कभी decrypt किए।
- Passwords को कभी वापस इनके original text में un-hash नहीं किया जा सकता — सिर्फ verify किया जा सकता है।
Chapter Quiz — Complete all 12 topics to unlock
0/12 topics done
Complete these topics first:
- Introduction to Django's Auth System
- The User Model Overview
- Setting Up a Login View
- Logout Functionality
- User Registration Form
- The login_required Decorator
- The permission_required Decorator
- Django Groups and Permissions
- Password Hashing in Django
- Session Authentication Basics
- Introduction to Custom User Models
- Sending Emails with Django